How we process, store, and protect your data under GDPR and applicable privacy regulations.
KEY TERMS
We process data only to operate the platform: running workloads, storing state, routing requests, and generating audit logs. No secondary use.
Choose your region. Data stays where you put it. EU, US, or APAC. Cross-region replication only when you explicitly configure it.
Transparent list of sub-processors. 30-day advance notice for changes. Right to object. No surprise data sharing.
72-hour notification SLA for confirmed breaches. Full incident report within 5 business days. Remediation timeline included.
Enterprise customers can request custom data processing terms.